Currently,
access to Red Hat OpenShift on IBM clusters is synchronized with IBM Cloud IAM users. This allows any person invited to join the account or has an existing IAM user to log in to OCP clusters.
This approach doesn't scale since it requires sending invitations to users. I would like to request the synchronization of principals authenticated via Trusted Profiles. This would allow SAML-based access or any other external IdP system to grant access without adding users manually to IAM.
This solution would allow to reuse existing access controls/mechanisms managed via external groups (such as LDAP) to grant access in alignment with existing processes.
| Idea priority | Urgent |
| Needed By | Yesterday (Let's go already!) |
By clicking the "Post Comment" or "Submit Idea" button, you are agreeing to the IBM Ideas Portal Terms of Use.
Do not place IBM confidential, company confidential, or personal information into any field.